CVE-2022-4841: Cross-site Scripting (XSS) - Stored in usememos/memos
Published Dec 29, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
Affected Software
1 affected component
usememos memos<0.9.1
Remediation
Event History
Dec 29, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4841?
CVE-2022-4841 refers to a vulnerability in the GitHub repository usememos/memos prior to version 0.9.1 that allows for Cross-site Scripting (XSS) attacks.
2
What is the severity of CVE-2022-4841?
CVE-2022-4841 has a severity value of 5.4, which is considered high.
3
How does CVE-2022-4841 affect Usememos Memos?
CVE-2022-4841 affects Usememos Memos versions prior to 0.9.1 by enabling stored Cross-site Scripting (XSS) attacks.
4
How can I fix CVE-2022-4841 in Usememos Memos?
To fix CVE-2022-4841, you should update Usememos Memos to version 0.9.1 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-4841?
The Common Weakness Enumeration (CWE) ID for CVE-2022-4841 is CWE-79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').